Google Cloud release notes

The following release notes cover the most recent changes over the last 60 days. For a comprehensive list of product-specific release notes, see the individual product release note pages.

You can also see and filter all release notes in the Google Cloud console or you can programmatically access release notes in BigQuery.

To get the latest product updates delivered to you, add the URL of this page to your feed reader, or add the feed URL directly.

September 18, 2026

Cloud Load Balancing
Feature

Managed workload identity for backend mTLS is generally available for the following Application Load Balancers:

  • Global external Application Load Balancers
  • Regional external Application Load Balancers
  • Cross-region internal Application Load Balancers
  • Regional internal Application Load Balancers

The key benefits are as follows:

  • Streamline certificate management: Automated certificate and trust management for backend mTLS through seamless integration with Certificate Authority Service and Certificate Manager.

  • Eliminate operational toil: Certificates are automatically rotated based on the workload identity pool's configuration, removing the complexity and manual bottleneck of private key provisioning and maintenance.

  • Improve visibility and governance: Gain visibility into communication between distributed services and proactively apply governance to workloads across environments.

For more information, see Backend mTLS with managed workload identity overview

Cloud Scheduler
Change

Cloud Scheduler is available in the following location:

  • asia-southeast3 (Bangkok, Thailand)
Gemini Enterprise
Feature

Gemini Enterprise: Support for new actions (Public Preview)

Support for new actions is available in Public Preview for the following data stores:

  • Microsoft OneDrive: Copy folder, move file, move folder, rename file, rename folder, share file or folder, and update file properties.
  • Microsoft Outlook: Create calendar, RSVP to event, and update calendar.
  • Microsoft SharePoint: Create list item, discard check out document, get list fields, get list item, list lists, share resource, update file properties, update list, update list item, and update page.
  • Microsoft Teams: Add member to channel, create channel, create chat, create schedule, create time off entry, update channel, update channel message, update chat, update chat message, and update time off entry.

For more information, see Connect a third-party data source.

Gemini Enterprise Agent Platform
Feature

xAI's Grok 4.6 is generally available

Grok 4.6 is now generally available (GA) and available for production use on the global endpoint and the US multi-region endpoint.

Breaking

Agent Platform SDK for Python version 2.0.1 is available

Version 2.0.1 of the Agent Platform SDK for Python (google-cloud-agentplatform) is now available. This release migrates generative AI modules to the Google Gen AI SDK, decouples the agent surface from google-cloud-aiplatform into a dedicated package, and introduces restructured namespaces.

For details and migration instructions from google-cloud-aiplatform, see the Agent Platform SDK for Python version 2.0.1 migration guide.

Google Cloud Contact Center as a Service
Fixed

This release addresses the following issues:

  • Fixed an issue where session metadata and data feed files were missing from external storage for chats that ended before the first message from the end-user.

  • Fixed an issue with Kustomer integrations where the caller's information didn't appear on the Incoming call page of the call adapter for direct-line inbound calls.

  • Fixed an issue with inbound mobile calls where the end-user leg of the call failed, returning Unknown error, while the agent leg connected normally.

  • Fixed an agent desktop issue where live call and chat data were lost.

  • Fixed an issue that occurred when the receiving agent in an agent-to-agent transfer didn't answer the call. The receiving agent was marked as active on the call indefinitely, even after the call ended.

  • Fixed an issue where the Dismiss button remained active after an agent sent a message, resulting in a 409 error when clicked.

  • Fixed an issue where duplicate "chat finished" events were reported when the end-user left a chat session at nearly the same time that the agent ended the chat session.

  • Fixed an issue where deflected calls were missing from the All Call History and Voice Inbound (IVR) History reports.

  • Fixed an issue that occurred when a direct inbound call was deflected to the agent's overcapacity queue, then that queue redirected to a SIP URI. The SIP redirect didn't include the custom SIP headers.

  • Fixed an issue where an in-queue announcement interval of several minutes for inbound IVR calls was incorrectly reduced to approximately 60 seconds.

  • Fixed an issue where calls that agents were unable to answer due to microphone failures were incorrectly reported as "picked up" in the Agent Activity Timeline report.

  • Fixed an issue where the system incorrectly marked agents as still being on a call after it ended, which either prevented them from changing their status to Available or silently blocked them from receiving new calls.

  • Fixed an issue where processing delays for ended calls caused timeout errors.

  • Fixed an issue where a sudden spike in calls bypassed capacity limits, causing agent availability to drop below required minimums.

  • Fixed an issue where the Agent Activity Timeline report incorrectly attributed manual agent logins and logouts to System instead of the appropriate agents.

  • Fixed an issue where calls with a missed offer became permanently stuck in the queue, preventing them from being routed to other available agents. This occurred with queues configured with multicast fallback disabled.

  • Fixed an issue where manual or cascade outbound calls that were canceled before connecting were missing from team-filtered Call History reports.

  • Fixed an issue that prevented over-capacity deflection from triggering when an agent warm-transferred an outbound call to a queue.

  • Fixed an issue where calls weren't correctly routed to the top-ranked agent when using agent priority overrides.

  • Fixed an issue where escalated voice calls were incorrectly reported as both answered and abandoned.

  • Fixed an issue where calls were missing from the All Call History and Voice Inbound History reports if the caller hung up before leaving a voicemail.

  • Fixed an issue where Salesforce click-to-dial outbound calls were incorrectly associated with the most recent open case instead of the case from which the call was initiated.

  • Fixed an issue where email accounts remained disconnected indefinitely after a temporary authentication failure.

  • Fixed an issue in Agent Assist where long periods of silence during calls caused connection timeouts, triggering false-positive error alerts.

  • Fixed an issue where the arrow-down-icon and arrow-up-icon arrows on the Agents > Filter Settings page were rendered at an incorrect scale.

  • Fixed an issue where incoming calls incorrectly created duplicate Salesforce accounts instead of linking to existing accounts.

  • Fixed an issue where the outbound call queue list displayed stale information, potentially causing calls to be placed in a queue that didn't match the agent's selected language.

  • Fixed an issue where the menus for transferring calls and forwarding calls to voicemail appeared in English instead of the agent's selected language.

  • Fixed an issue where the wrap-up disposition panel froze after a network reconnection even though the submission had completed successfully.

  • Fixed an issue where outbound, click-to-dial calls initiated in Salesforce incorrectly linked to and reassigned ownership of other cases associated with the same phone number.

  • Fixed an issue where the agent adapter went blank and prevented new calls from reaching the agent if an end-user hung up immediately after the agent received the call notification.

  • Fixed an issue where calls that failed to connect got stuck in a silent 'connecting' state in the call adapter.

  • Fixed an issue where Salesforce CRM connections dropped for organizations enforcing OAuth Refresh Token Rotation.

  • Fixed an issue where part of an agent's audio was dropped from recordings when a virtual task assistant ran in the middle of a call.

  • Fixed a web SDK issue where menus in the pre-chat and chat screens didn't comply with WAI-ARIA keyboard navigation standards.

  • Fixed a web SDK issue where screen readers couldn't identify the purpose of the Text size options for the chat screen.

Announcement

Advanced reporting dashboards 6.4

We've released version 6.4 of the advanced reporting dashboards.

Feature

Real-time Agent Monitoring dashboard: new Active call ID(s) column

The Real-time Agent Monitoring dashboard now has an Active Call ID(s) column in the Live Agent Data table. The column displays the call ID(s) for any call in a connecting, connected, or reconnecting state for the agent. If an agent is handling multiple concurrent calls, the call IDs appear in a comma-separated list. The Active Call ID(s) column reduces the number of steps required for supervisors to identify active calls during live monitoring.

Feature

Improved filtering by team

We made the following changes to team-based filtering:

  • Renamed the Teams filter to Agent Teams to clarify that it filters by the agent team handling the interactions. This change is in the Real-time Queue Monitoring - Calls, Real-time Queue Monitoring - Chats, Real-time Connected - Calls, and Real-time Connected - Chats dashboards. For more information, see Queue monitoring dashboards, Real-time Connected - Calls dashboard, and Real-time Connected - Chats dashboard.

  • Added a Queue Teams filter to the Real-time Queued - Calls and Real-time Queued - Chats dashboards. This lets you filter queued interactions by the team assigned to the queue.

Feature

Improved the Real-time Calls and Real-time Chats dashboards

We made the following dashboard improvements:

  • Real-time Calls - Calls Connected dashboard. Added the following columns to the Connected Calls table:

    • Total Consumer Talk Time. Total time since the call first connected to a virtual agent or a human agent.

    • Total Hold Time. Total time the call has spent on hold so far, including a hold currently in progress.

  • Real-time Chats - Chats Connected dashboard. Added the following column to the Connected Chats table:

    • Total Consumer Chat Time. Total time since the chat first connected to a virtual agent or a human agent.
Feature

Real-time Calls - Calls Queued dashboard: new Projecting column

The Real-time Calls - Calls Queued dashboard has a new Projecting column in the Call Queued table. Indicates whether the routing engine (deltacast) is currently projecting this queued call to an available agent.

Feature

Advanced reporting available in French Canadian

All advanced reporting dashboards and Explores are now available in French Canadian. When you select French Canadian as your profile language in the CCAI Platform portal, these dashboards and Explores display in that language.

Administrators: There's a new Français (CAN) option when you click Admin > Change Language in the CCAI Platform portal.

Fixed

This release addresses the following issues:

  • Fixed an issue where the formatting of numeric values was inconsistent across tiles.

  • Fixed an issue where column headers, filter labels, and tile titles didn't immediately switch to a newly selected language.

  • Fixed an issue where the Productive Agents column in the tables of the Queue Group Performance - All dashboard didn't display values appropriate to the queue group settings.

  • Fixed an issue in the Call Queue Metrics (Historical) Explore where filtering by Agent Name without including it as a visible column resulted in zero rows being returned.

  • Fixed an issue that affected calls to a sub-menu that were deflected using Custom After Hours Deflection to a message. These calls were incorrectly attributed to the parent menu in the All Queued Interactions report.

  • Fixed the effectiveness of the Direction filter in the following dashboards:

    • Agent Performance. The Agent Productivity Detailed – Calls and Agent Productivity Detailed – Chats tables correctly reflect the filter setting.

    • Real-time Agent Monitoring. The Agent Performance table and historical metrics tiles correctly reflect the filter setting.

    • All Interactions – Calls and All Interactions – Chats. The IVR Interactions (calls only) and Virtual Agent Interactions tables correctly reflect the filter setting.

  • Fixed an issue with the Queue Performance - Calls dashboard when short abandons were present in the specified date range. The Avg Queue Time column in the Queue Summary table incorrectly displayed the raw sum of queue durations instead of a true average.

  • Fixed an issue where team filters didn't apply correctly when generating the Individual Call History Report and the Individual Chat History Report. This resulted in the inclusion of data from unmanaged queues.

  • Fixed an issue where French Canadian translations for several dashboard metrics and labels were incorrect, incomplete, or missing.

  • Fixed the following issues with the Real-time Calls - Calls Queued dashboard:

    • The Total Queued Now metric didn't include callers who were returned to the queue after an automated-answer detection miss.

    • The Current Max Queue Wait Time (H:M:S) and Current Avg Queue Wait Time (H:M:S) metrics mistakenly measured from a caller's original entry into the queue, rather than from their most recent return to the queue.

  • Fixed an issue where a gray bar appeared at the bottom of the advanced reporting dashboards, preventing a full view of the dashboards.

Memorystore for Valkey Model Armor
Feature

Filter version v4 is available and set as the default for the Latest alias. Filter version v3 is promoted to the Stable alias in all supported regions except the following:

  • In asia-northeast3, v1 remains the Stable version.
  • In australia-southeast2, v3 becomes the Stable version on September 25, 2026.

If your templates use the Stable alias, they automatically upgrade to v3 when v3 becomes Stable in that region.

Filter versions v1 (except in asia-northeast3, and starting September 25, 2026 in australia-southeast2) and v2 transition to Legacy status and retire on December 17, 2026. If your templates are explicitly configured with v1 or v2 in regions where those versions are in Legacy status, you must migrate them to v3 or the Stable alias before December 17, 2026.

For more information, see Version release timeline and Model Armor filter version history.

September 17, 2026

Apigee hybrid
Announcement

v1.16.10

On September 17, 2026 we released an updated version of the Apigee hybrid software, v1.16.10.

Fixed

Fixed in this release

Bug ID Description
556750755 Fixed an issue where EventFlow (Server-Sent Events) dropped or truncated events following a large (>16 KB) event under load on the http-adaptor datapath.
547712217 Fixed an issue where EventFlow (Server-Sent Events) responses larger than 16 KB could be truncated or corrupted across socket reads.
519729209 Fixed a SAML XML Signature Wrapping (XSW) vulnerability in the ValidateSAMLAssertion policy.
514384893 Hardened the Script policy to block server-side request forgery (SSRF) to link-local addresses.
505645076 Fixed a security issue in the OAuthV2 policy to prevent unauthorized token injection via HTTP form parameters.
505543289 Fixed thread-safety issues in the Netty client connection pool and channel lifecycle.
503817773 Improved security in the OAuthV2 policy implicit grant redirect_uri validation.
502268966 Apigee hybrid now supports optional decoding of percent-encoded path separators (%2F and %5C) before flow selection via the request.path.decode.encoded.separators proxy property.
480770263 Fixed an issue in the SpikeArrest policy to handle edge cases that previously caused NullPointerException and 500 errors.
472526232 Improved SAML assertion validation in the ValidateSAMLAssertion policy against entity and comment injection.
470375542 Fixed a memory leak in WSFrameDecoder that could result in a spike in 503 responses with no_healthy_upstream errors.
449228485 Apigee hybrid now supports configuring custom Kubernetes PodDisruptionBudget (minAvailable or maxUnavailable) values for Apigee hybrid components in your overrides.yaml file.
402250928 Apigee hybrid now supports routing outbound calls from AI policies, such as the Model Armor and semantic caching policies, through an HTTP forward proxy.
Feature

Kubernetes 1.36 support

Apigee hybrid v1.16.10 adds support for Kubernetes 1.36 on Google Kubernetes Engine (GKE), Google Distributed Cloud Virtual for VMware (vSphere), Google Distributed Cloud Virtual for bare metal, Amazon EKS, Azure AKS, and Rancher Kubernetes Engine (RKE2).

For more information, see Supported platforms.

Feature

Forward proxy support for AI policies

Apigee hybrid v1.16.10 adds forward proxy support for AI policies, such as the Model Armor and semantic caching policies. Outbound calls from these policies can now be routed through an HTTP forward proxy.

For more information, see Configure a forward proxy, Get started with the Model Armor policies, and Get started with semantic caching policies.

Security
Bug ID Description
N/A Security fixes for apigee-asm-ingress.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-asm-istiod.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-connect-agent.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-fluent-bit.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-hybrid-cassandra-client.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-mart-server.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-mint-task-scheduler.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-open-telemetry-collector.
This addresses the following vulnerability:
N/A Security fixes for apigee-operators.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-prom-prometheus.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-prometheus-adapter.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-redis.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-runtime.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-synchronizer.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-watcher.
This addresses the following vulnerabilities:
BigQuery
Feature

You can add unit tests to pipelines to validate your SQL transformation logic against mock datasets. Unit tests for pipelines are generally available (GA).

Cloud Asset Inventory
Feature

The following resource type is publicly available through the ExportAssets, ListAssets, BatchGetAssetsHistory, QueryAssets, and Feed APIs.

  • Cloud TPU API
    • tpu.googleapis.com/QueuedResource
Cloud SQL for MySQL
Change

Cloud SQL for MySQL now automatically enables point-in-time recovery (PITR) in a separate, asynchronous operation after disaster recovery (DR) switchover and replica failover operations complete. Because PITR enablement no longer blocks switchover and replica failover, these operations complete faster, helping you reduce your recovery time.

For more information, see Use advanced disaster recovery (DR).

Cloud SQL for PostgreSQL
Change

Cloud SQL for PostgreSQL now automatically enables point-in-time recovery (PITR) in a separate, asynchronous operation after disaster recovery (DR) switchover and replica failover operations complete. Because PITR enablement no longer blocks switchover and replica failover, these operations complete faster, helping you reduce your recovery time.

For more information, see Use advanced disaster recovery (DR).

Compute Engine
Feature

Generally available: The storage-optimized Z4D machine series is generally available for Compute Engine. Powered by AMD EPYC Turin processors and Titanium offload processors, Z4D instances are purpose-built for low core usage and high storage density workloads such as:

  • SQL, NoSQL, and vector databases
  • Data analytics and data warehouses
  • Search
  • Parallel file systems for AI/ML

The Z4D machine series delivers up to 3 TB of memory and 42,000 GiB of local Titanium SSD capacity. Z4D also supports up to 400 Gbps of network bandwidth using two physical NICs. Z4D instances are available in predefined standardlssd and highlssd machine shapes.

For more information, see Storage-optimized machine family.

Container Optimized OS
Change

cos-beta-133-19999-44-44

Kernel Docker Containerd GPU Drivers
COS-6.18.48 v29.4.3 v2.3.4 See List
Change

cos-129-19506-448-36

Kernel Docker Containerd GPU Drivers
COS-6.12.105 v27.5.1 v2.2.7 See List
Change

Fixed CVE-2026-56391 in sys-apps/coreutils.

Security

Fixed CVE-2026-56391 in sys-apps/coreutils.

Security

Fixed CVE-2026-58470 in net-misc/wget.

Security

Fixed CVE-2026-80590 in the Linux kernel.

Security

Fixed CVE-2026-59890 in dev-python/setuptools.

Security

Fixed CVE-2026-80737 in the Linux kernel.

Security

Upgraded net-libs/nghttp2 to 1.69.0 and fixed CVE-2026-58055.

Security

Fixed CVE-2026-80788 in the Linux kernel.

Security

Fixed CVE-2026-80789 in the Linux kernel.

Security

Fixed CVE-2026-80791 in the Linux kernel.

Security

Fixed CVE-2026-80792 in the Linux kernel.

Security

Fixed CVE-2026-80793 in the Linux kernel.

Security

Fixed CVE-2026-80805 in the Linux kernel.

Security

Fixed CVE-2026-80806 in the Linux kernel.

Security

Fixed CVE-2026-80808 in the Linux kernel.

Security

Fixed CVE-2026-80837 in the Linux kernel.

Security

Fixed CVE-2026-80838 in the Linux kernel.

Security

Fixed CVE-2026-80839 in the Linux kernel.

Security

Fixed CVE-2026-80842 in the Linux kernel.

Security

Fixed CVE-2026-80843 in the Linux kernel.

Security

Fixed CVE-2026-80845 in the Linux kernel.

Security

Fixed CVE-2026-80852 in the Linux kernel.

Security

Fixed CVE-2026-80854 in the Linux kernel.

Security

Fixed CVE-2026-80855 in the Linux kernel.

Security

Fixed CVE-2026-80856 in the Linux kernel.

Security

Fixed CVE-2026-80862 in the Linux kernel.

Security

Fixed CVE-2026-80916 in the Linux kernel.

Security

Fixed CVE-2026-80917 in the Linux kernel.

Change

cos-125-19216-655-28

Kernel Docker Containerd GPU Drivers
COS-6.12.105 v27.5.1 v2.2.7 See List
Feature

Fixed a performance issue in the GVE driver on multi-NUMA systems.

Fixed

Upgraded net-libs/libnftnl to v1.2.9.

Security

Fixed CVE-2026-80590 in the Linux kernel.

Security

Fixed CVE-2026-80737 in the Linux kernel.

Security

Fixed CVE-2026-80788 in the Linux kernel.

Security

Fixed CVE-2026-80789 in the Linux kernel.

Security

Fixed CVE-2026-80791 in the Linux kernel.

Security

Fixed CVE-2026-80792 in the Linux kernel.

Security

Fixed CVE-2026-80793 in the Linux kernel.

Security

Fixed CVE-2026-80805 in the Linux kernel.

Security

Fixed CVE-2026-80806 in the Linux kernel.

Security

Fixed CVE-2026-80808 in the Linux kernel.

Security

Fixed CVE-2026-80837 in the Linux kernel.

Security

Fixed CVE-2026-80838 in the Linux kernel.

Security

Fixed CVE-2026-80839 in the Linux kernel.

Security

Fixed CVE-2026-80842 in the Linux kernel.

Security

Fixed CVE-2026-80843 in the Linux kernel.

Security

Fixed CVE-2026-80845 in the Linux kernel.

Security

Fixed CVE-2026-80852 in the Linux kernel.

Security

Fixed CVE-2026-80854 in the Linux kernel.

Security

Fixed CVE-2026-80855 in the Linux kernel.

Security

Fixed CVE-2026-80856 in the Linux kernel.

Security

Fixed CVE-2026-80862 in the Linux kernel.

Security

Fixed CVE-2026-80916 in the Linux kernel.

Security

Fixed CVE-2026-80917 in the Linux kernel.

Change

Runtime sysctl changes:

  • Changed: net.ipv4.udp_mem: 188034 250714 376068 -> 188034 250715 376068

Change

cos-117-18613-731-21

Kernel Docker Containerd GPU Drivers
COS-6.6.153 v24.0.9 v1.7.34 See List
Security

Fixed CVE-2026-80590 in the Linux kernel.

Security

Fixed CVE-2026-80737 in the Linux kernel.

Security

Fixed CVE-2026-80788 in the Linux kernel.

Security

Fixed CVE-2026-80789 in the Linux kernel.

Security

Fixed CVE-2026-80791 in the Linux kernel.

Security

Fixed CVE-2026-80792 in the Linux kernel.

Security

Fixed CVE-2026-80793 in the Linux kernel.

Security

Fixed CVE-2026-80805 in the Linux kernel.

Security

Fixed CVE-2026-80806 in the Linux kernel.

Security

Fixed CVE-2026-80808 in the Linux kernel.

Security

Fixed CVE-2026-80842 in the Linux kernel.

Security

Fixed CVE-2026-80843 in the Linux kernel.

Security

Fixed CVE-2026-80852 in the Linux kernel.

Security

Fixed CVE-2026-80854 in the Linux kernel.

Security

Fixed CVE-2026-80855 in the Linux kernel.

Security

Fixed CVE-2026-80856 in the Linux kernel.

Security

Fixed CVE-2026-80916 in the Linux kernel.

Security

Fixed CVE-2026-80917 in the Linux kernel.

Change

cos-121-18867-584-23

Kernel Docker Containerd GPU Drivers
COS-6.6.153 v27.5.1 v2.0.10 See List
Security

Fixed CVE-2026-80590 in the Linux kernel.

Security

Fixed CVE-2026-80737 in the Linux kernel.

Security

Fixed CVE-2026-80788 in the Linux kernel.

Security

Fixed CVE-2026-80789 in the Linux kernel.

Security

Fixed CVE-2026-80791 in the Linux kernel.

Security

Fixed CVE-2026-80792 in the Linux kernel.

Security

Fixed CVE-2026-80793 in the Linux kernel.

Security

Fixed CVE-2026-80805 in the Linux kernel.

Security

Fixed CVE-2026-80806 in the Linux kernel.

Security

Fixed CVE-2026-80808 in the Linux kernel.

Security

Fixed CVE-2026-80842 in the Linux kernel.

Security

Fixed CVE-2026-80843 in the Linux kernel.

Security

Fixed CVE-2026-80852 in the Linux kernel.

Security

Fixed CVE-2026-80854 in the Linux kernel.

Security

Fixed CVE-2026-80855 in the Linux kernel.

Security

Fixed CVE-2026-80856 in the Linux kernel.

Security

Fixed CVE-2026-80917 in the Linux kernel.

Dataform
Feature

You can use unit tests to test Dataform actions against mock data with an expected result set. Dataform unit tests are generally available (GA).

Gemini Enterprise
Announcement

Gemini Enterprise: Gemini Code Assist availability update for subscriptions

If you're getting a new Gemini Enterprise Standard or Plus subscription or renewing an existing subscription online, the subscription no longer includes access to Gemini Code Assist features. Existing subscriptions that include Gemini Code Assist features can still access the features until the end of their subscription term.

Instead of Gemini Code Assist, you can use Antigravity for IDEs with AI developer tools. For more information, see AI developer tools overview.

If you're still looking to use Gemini Code Assist with your Gemini Enterprise licenses, you can obtain a new Gemini Enterprise subscription that includes Gemini Code Assist by contacting Google Cloud sales.

Feature

Gemini Enterprise: Voice input for the chat box

You can speak your queries and prompts to Gemini Enterprise. Use the microphone button to record your voice, review and edit the transcribed text, and then submit the text.

This feature is generally available (GA). To make voice input available to users, a Gemini Enterprise administrator must turn on the Enable speech-to-text toggle in the Google Cloud console.

For more information, see the following:

Gemini Enterprise Agent Platform
Feature

Gemini Omni Flash supports stateful and streaming video generation (Preview)

Gemini Omni Flash supports stateful (store: true) and server-sent event (SSE) streaming (stream: true) video generation in the Interactions API in Preview. You can temporarily store generated videos and interaction state on the server, stream status updates and final outputs over an SSE connection, or retrieve completed asynchronous interactions using unary or streaming GET requests.

For more information, see Generate videos from text.

Google Cloud Armor
Feature

Cloud Armor managed rulesets protect your backend services and APIs from a wide range of web application threats using threat signatures which are automatically kept up-to-date. For more information, see Managed rules overview. This feature is available in Preview.

Google Distributed Cloud (software only) for VMware
Announcement

Google Distributed Cloud (software only) for VMware 1.34.900-gke.135 is now available for download. To upgrade, see Upgrade a cluster. Google Distributed Cloud 1.34.900-gke.135 runs on Kubernetes v1.34.7-gke.200.

If you use a third-party storage vendor, check the listing of our previously-qualified storage partners.

After a release, it takes approximately 7 to 14 days for the version to become available for use with GKE On-Prem API clients: the Google Cloud console, the gcloud CLI, and Terraform.

Fixed

The following issues were fixed in 1.34.900-gke.135:

  • Fixed vulnerabilities listed in Vulnerability fixes.
  • Fixed an issue where user clusters repeatedly alternated between Reconciling and Running states if the management cluster configured a different pod density than the user cluster.
  • Updated etcd to v3.5.33-0-gke.3 to address security vulnerabilities CVE-2026-46595 and CVE-2026-39821.
  • Fixed an issue where gkectl diagnose and preflight validations failed to locate PersistentVolume datastores for user clusters deployed in a separate vSphere datacenter from the admin cluster (cpNodesInAdminDatacenter: true).
  • Fixed an issue where deleting a cluster could get stuck because the node pool controller attempted to recreate machine resources while deletion was in progress.
Google Distributed Cloud (software only) for bare metal
Announcement

Google Distributed Cloud (software only) for bare metal 1.34.900-gke.135 is now available for download. To upgrade, see Upgrade clusters. Google Distributed Cloud for bare metal 1.34.900-gke.135 runs on Kubernetes v1.34.7-gke.200.

After a release, it takes approximately 7 to 14 days for the version to become available for installations or upgrades with the GKE On-Prem API clients: the Google Cloud console, the gcloud CLI, and Terraform.

If you use a third-party storage vendor, check the listing of our previously-qualified storage partners.

Fixed

The following issues were fixed in 1.34.900-gke.135:

  • Fixed vulnerabilities listed in Vulnerability fixes.
  • Fixed an issue where the status for Ingress resources was not updated when using bundled Ingress.
  • Fixed an issue where user clusters repeatedly alternated between reconciling and running states if the management cluster had a different pod density configuration than the user cluster.
  • Updated etcd to v3.5.33-0-gke.3 to address security vulnerabilities CVE-2026-46595 and CVE-2026-39821.
  • Fixed an issue where deleting a cluster could get stuck because the node pool controller attempted to recreate machine resources while cluster deletion was in progress.
Google Kubernetes Engine
Change

(2026-R39) Version updates

GKE cluster versions have been updated.

New versions available for upgrades and new clusters.

The following versions are now available for new GKE clusters, and for manual control plane upgrades and node upgrades for existing clusters. For more information about versioning and upgrades, see GKE versioning and support and About GKE cluster upgrades.

Rapid channel

Regular channel

  • Version 1.35.8-gke.1036000 is now the default version for cluster creation in the Regular channel.
  • The following versions are now available in the Regular channel:
  • The following versions are no longer available in the Regular channel:
    • 1.34.10-gke.1236000
    • 1.35.7-gke.1222000
    • 1.36.3-gke.1640000 is deprecated in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:

Stable channel

  • Version 1.34.10-gke.1236000 is now available in the Stable channel.
  • Version 1.34.10-gke.1106000 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:

Extended channel

No channel (deprecated)

Security

(2026-R39) Security updates

This release includes new GKE versions that use updated Container-Optimized OS images. These updated images are cumulative, incorporating security fixes from all Container-Optimized OS versions released since the previous GKE release.

To identify the specific vulnerabilities that were resolved in each updated Container-Optimized OS image, see the Security release notes for that image. The following table includes links to the release notes for each updated Container-Optimized OS image:

GKE version Container-Optimized OS version Details
1.37.0-gke.3503000 cos-129-19506-299-82 cos-129-19506-299-82 release notes

Change

(2026-R39) Version updates

  • Version 1.34.10-gke.1236000 is now available in the Stable channel.
  • Version 1.34.10-gke.1106000 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
Change

(2026-R39) Version updates

  • Version 1.35.8-gke.1036000 is now the default version for cluster creation in the Regular channel.
  • The following versions are now available in the Regular channel:
  • The following versions are no longer available in the Regular channel:
    • 1.34.10-gke.1236000
    • 1.35.7-gke.1222000
    • 1.36.3-gke.1640000 is deprecated in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
Change

(2026-R39) Version updates

Change

(2026-R39) Version updates

Change

(2026-R39) Version updates

Looker
Announcement

Looker 26.18 will roll out to Looker (original) instances on the following schedule:

  • Expected deployment start: Monday, September 21, 2026
  • Expected final deployment and download available: Sunday, October 4, 2026

Looker 26.18 is expected to include the following changes, features, and fixes.

Fixed

An issue has been fixed where custom content theme fonts were improperly applied to the Look edit mode bar. This feature now performs as expected.

Fixed

An issue has been fixed where downloading a dashboard as a CSV or ZIP file could result in a 500 error if any dashboard elements lacked an explicit title. This feature now performs as expected.

Fixed

An issue has been fixed where links created using the LookML link parameter could return a 500 error if no label was specified. This feature now performs as expected.

Fixed

An issue has been fixed where dashboard filter token chips didn't display an active highlighted background when a filter value was selected. This feature now performs as expected.

Fixed

An issue has been fixed where the Git connection test could fail to recognize Git credentials as sufficient if a branch protection rule on the Git provider restricted temporary branches. This feature now performs as expected.

Fixed

An issue has been fixed where analytic models that referenced cross-database, schema-qualified, or dot-delimited table names failed to compile in BigQuery and Snowflake DDL generation. This feature now performs as expected.

Fixed

An issue has been fixed where custom tooltips in Single Record visualizations appeared at the bottom of the Explore panel rather than directly beneath the selected row. This feature now performs as expected.

Fixed

An issue has been fixed where dashboard filter tokens and popover menus could fail to inherit fonts from custom themes. This feature now performs as expected.

Fixed

An issue has been fixed where dragging series between Y-axes on pivoted Cartesian charts could cause the Explore page to crash or prevent visualization configurations from being saved. This feature now performs as expected.

Fixed

An issue has been fixed in Explores where you couldn't scroll within the Chart Config Editor dialog when editing JSON visualization configurations. This feature now performs as expected.

Fixed

An issue has been fixed where scheduled PDF deliveries to Cloud Storage could produce corrupted files and unexpectedly replace spaces in filenames with underscores. This feature now performs as expected.

Fixed

An issue has been fixed where attempting to visualize pivoted query results in SQL Runner resulted in a TypeError configuration error. This feature now performs as expected.

Fixed

API requests that target a LookML project whose files or directories aren't found on the instance now return a 404 Not Found error instead of a 500 Internal Server Error.

Fixed

In Conversational Analytics, the Open in Explore button and sidebar exploration links are now hidden or disabled with explanatory tooltips when you lack explore permissions for the underlying model.

Fixed

The embed preload page now supports custom theming using the theme URL query parameter.

Fixed

Donut Multiples visualizations now automatically hide overlapping value labels.

Fixed

An issue has been fixed in self-service analytics where CSV and Excel uploads to BigQuery and Snowflake could fail or corrupt data when files contained multiline headers, leading numeric characters, UTF-8 BOM markers, or special characters. This feature now performs as expected.

Fixed

An issue has been fixed where creating a shared branch based on the production branch in a bare repository project could initialize from stale remote commits, causing the Looker IDE to immediately report the branch as being behind production. This feature now performs as expected.

Fixed

An issue has been fixed where scheduled deliveries intermittently failed with permission errors such as Cannot send all results because user permissions were incorrectly cached across scheduled jobs on worker threads. This feature now performs as expected.

NetApp Volumes
Feature

Organization Policy Service custom constraints are available for Google Cloud NetApp Volumes. You can use custom constraints to control how NetApp Volumes is used in your organization. For example, you can restrict storage pool or volume capacity, or enforce that storage pools are created only with Premium or Extreme service levels.

For more information, see Custom organization policy constraints.

Oracle Database@Google Cloud
Feature

For Exadata Database Service, Oracle Database@Google Cloud is available in europe-west12 (Turin, Italy) region.

For a list of supported locations, see Supported regions and zones.

Spanner
Feature

Spanner queues are generally available (GA). Spanner queues provide transactional messaging to help you manage asynchronous work. The feature pairs this capability with the scalability and reliability of Spanner, letting you build event-driven applications. For more information, see the Spanner queues overview.

September 16, 2026

Backup and DR
Feature

You can now use auto-protection policies and resource labels to automatically protect Compute Engine instances and Persistent Disks at scale in Backup and DR. This feature allows you to automatically assign a backup plan to qualifying resources across projects based on user-defined labels. This feature is in Preview. For more information, see Automate resource protection.

BigQuery
Feature

You can use the migration lineage service to visualize the data flow and connections in your source database and help you plan a BigQuery data warehouse migration. This feature is in Preview.

Cloud Number Registry
Breaking
Datastream
Feature

Datastream now supports MongoDB extended JSON canonical mode as the default format for new streams from MongoDB sources to BigQuery destinations.

Canonical mode provides higher data fidelity by explicitly labeling every BSON type to prevent precision loss during data exchange.

For more information, see the following:

Filestore
Feature

Small capacity Filestore instances for the Regional service tier are generally available (GA). Small capacity instances start at 100 GiB and scale in 1 GiB increments, providing an option for development, testing, and applications with low traffic or basic storage needs.

For more information, see Small capacity instances.

Gemini Enterprise Agent Platform
Feature

CodeMender updates (v0.8.0)

This release introduces updates to CodeMender:

  • Gemini 3.8 Flash default: Gemini 3.8 Flash (gemini-3.8-flash) is now supported and enabled as the default model for CodeMender CLI sessions, delivering faster inference and improved reasoning. A one-time notice in the CLI informs users when the new default is active.
  • Tool payload guardrails: Introduced safe output limits for file reading (2 MiB) and codebase grep search (512 KiB) with centered match context windows, eliminating payload overflow errors and improving stability during large repository scans.
  • Bug fixes:
    • Fixed an issue where shell detection and command execution on Windows could fail during repository resets and exploit verification when Git Bash was installed in standard registry or non-PATH locations.
    • Fixed an issue in cm verify where verified findings could report "not found" or fail to persist confidence and status upon session completion or resumption.
    • Fixed syntax errors in generated verification scripts caused by invalid regex escaping in grep assertions during cm verify.
    • Prevented HTTP 409 lease conflict errors during long-running sessions by ensuring streaming HTTP connections are promptly released.

For more information, see CodeMender documentation.

Secure Source Manager
Feature

Secure Source Manager webhooks now support Pull request comment trigger events. You can configure webhooks to trigger notifications whenever a comment is added, edited, or deleted on a pull request.

For more information, see the Pull request comment event payload in the Webhooks overview.

Security Command Center
Feature

You can use the following MCP server endpoints to enable LLM agents to perform investigative and management tasks in Security Command Center.

This feature is in Preview.

Virtual Private Cloud
Feature

General Availability: You can add Dynamic NICs to the same VPC network used by other network interfaces of a Compute Engine instance. For more information, see Multiple network interfaces.

Feature

General Availability: VPC Flow Logs supports logging for App Engine resources that are configured with Direct VPC egress. For more information, see Serverless flows and ServerlessDetails field format.

Feature

General Availability: VPC Flow Logs adds the following metadata annotations for Private Service Connect:

  • src_psc_interface and dest_psc_interface
  • psc.consumer_connection
  • psc.psc_endpoint.name
  • psc.psc_attachment.name

For more information, see Record format.

September 15, 2026

Artifact Registry
Feature

Artifact Registry support for managing Conda packages with Artifact Registry repositories is in Preview. For more information, see Get started with Conda packages.

Batch
Issue
Carbon Footprint
Change

For the July 2026 data release (published mid-September 2026), we have upgraded the carbon model to version 17 and implemented the following updates:

Updating Scope 1 & 3 Emissions from Google's Corporate Footprint

Updating Inputs for Scope 2 Market-Based Emissions Calculations

  • Updated annual renewable electricity allocation percentages in accordance with the 2026 Google Environmental Report.
  • Refreshed background annual emissions factors using updated government data sources across Scope 1, Scope 2, and Scope 3. Note that Scope 2 location-based emissions continue to be calculated using hourly greenhouse gas emission factors. Learn more in the Scope 2 market-based allocation documentation.
  • Incorporated marketplace purchases of Granular Certificates (Type B certificates / T-EACs) covering a significant portion of electricity load across carbon-intensive regions.
  • Granular certificate purchases represent market-based accounting allocations. Customers seeking to minimize emissions are encouraged to prioritize regions with high Carbon Free Energy (CFE) scores for new workloads.

Regional Accounting & Boundary Updates

  • Aligned European clean energy matching boundaries with updated RE100 criteria.
  • Corrected country mapping configurations in annual emission factor scripts to resolve historical data discrepancies across select Asian market regions (e.g., asia-east2, asia-northeast3).

To correct your July emissions data, schedule a manual data backfill for the month.

Cloud Asset Inventory
Feature

The following resource type is publicly available through the ExportAssets, ListAssets, BatchGetAssetsHistory, QueryAssets, and Feed APIs.

  • Network Management API
    • networkmanagement.googleapis.com/VpcFlowLogsConfig
Compute Engine
Feature

Public preview: Network-optimized C4N machine type with 375 GiB to 12,000 GiB of attached Titanium SSD are now available in Preview. You don't have to request allowlist approval.

For more information, see C4N machine series.

Confidential Space
Announcement

A new Confidential Space image (260800) is available. Support for Confidential Space on H100 GPU (a3-highgpu-1g machine family) with Intel Trust Authority (ITA) attestation is generally available.

Gemini Enterprise Agent Platform
Feature

Reinforcement learning fine-tuning in the Google Cloud console (Preview)

You can create, monitor, and test reinforcement learning fine-tuning jobs for Gemini models in the Google Cloud console (Preview). From the Models > Tuning page, you can configure Python code or model-based reward functions, test reward logic against sample prompts before launching a job, track training and evaluation metrics in real time, and test tuned checkpoints in Agent Studio.

For more information, see Quick start: Reinforcement learning fine-tuning using the console.

Google Cloud Contact Center as a Service
Announcement

Mobile SDKs 2.16.2

We've released version 2.16.2 of the mobile SDKs.

Feature

Chat check-in for the Mobile SDKs

Chat check-in is now available for the mobile SDKs. Chat check-in ensures that end-users are present and ready to engage before the system connects them to a human agent. This decreases the average agent handle time by eliminating the time lost when agents wait for end-users who have abandoned a chat.

For more information, see:

Feature

New "is typing" indicator in the Mobile SDKs

The mobile SDKs now display an "is typing" indicator to the end-user when an agent is typing.

Fixed

We've addressed the following issues.

Android and iOS SDKs:

  • Fixed an issue that occurred after force-closing a mobile app while the check-in timeout dialog was displayed. When the app was relaunched, the check-in dialog didn't reappear.

  • Fixed an issue where mobile inbound calls didn't connect.

iOS SDK only:

  • Fixed an issue where end-users received duplicate end-of-chat notifications when a virtual agent ended a conversation.

  • Fixed an issue where a virtual agent's final message appeared out of order during a chat escalation.

  • Fixed an issue where apps didn't upload logs when the server returned a relative URL.

Android SDK only:

  • Fixed an issue where a five-second delay occurred between session creation and the initial chat fetch, significantly delaying when the message appeared.
Google Distributed Cloud (software only) for VMware
Announcement

Google Distributed Cloud (software only) for VMware 1.33.1200-gke.83 is now available for download. To upgrade, see Upgrade clusters. Google Distributed Cloud 1.33.1200-gke.83 runs on Kubernetes v1.33.11-gke.100.

If you use a third-party storage vendor, check the listing of our previously-qualified storage partners.

After a release, it takes approximately 7 to 14 days for the version to become available for use with GKE On-Prem API clients: the Google Cloud console, the gcloud CLI, and Terraform.

Fixed

The following issues were fixed in 1.33.1200-gke.83:

Google Distributed Cloud (software only) for bare metal
Announcement

Google Distributed Cloud (software only) for bare metal 1.33.1200-gke.83 is now available for download. To upgrade, see Upgrade clusters. Google Distributed Cloud for bare metal 1.33.1200-gke.83 runs on Kubernetes v1.33.11-gke.100.

After a release, it takes approximately 7 to 14 days for the version to become available for installations or upgrades with the GKE On-Prem API clients: the Google Cloud console, the gcloud CLI, and Terraform.

If you use a third-party storage vendor, check the listing of our previously-qualified storage partners.

Fixed

The following issues were fixed in 1.33.1200-gke.83:

Google SecOps
Feature

Grok filter match_all option in parser syntax

The Google SecOps parser syntax is updated to support the match_all option within the Grok filter. This allows parsers to extract all non-overlapping pattern occurrences within a field, rather than returning only the first match.

For more information, see Parser syntax reference.

Google SecOps SIEM
Feature

Grok filter match_all option in parser syntax

The Google SecOps parser syntax is updated to support the match_all option within the Grok filter. This allows parsers to extract all non-overlapping pattern occurrences within a field, rather than returning only the first match.

For more information, see Parser syntax reference.

NetApp Volumes
Announcement

Effective September 15, 2026, you can't create new Flex File storage pools, but existing pools remain supported. Support for the Flex File service level of Google Cloud NetApp Volumes ends on June 15, 2027. You must migrate your data from Flex File to the Flex Unified service level. For more information, see Migration to Flex Unified service level.

Policy Intelligence
Feature

Policy Troubleshooter now supports troubleshooting access for agent identities. You can troubleshoot IAM allow policies, deny policies, and principal access boundary policies for agents acting under their own authority by entering the agent's principal identifier or by troubleshooting with an error ID from an access denial event. To learn more, see Troubleshooting access.

September 14, 2026

Apigee hybrid
Announcement

hybrid v1.17.0

On September 14, 2026 we released an updated version of the Apigee hybrid software, 1.17.0.

Feature

Model Context Protocol (MCP) support

Apigee hybrid now supports Model Context Protocol (MCP), an open protocol that lets agentic AI applications use your APIs as tools through managed MCP endpoints. Apigee hybrid routes, authorizes, and secures these MCP tool calls the same way it manages your other APIs, so you don't need to run or maintain your own MCP servers.

MCP support is an optional feature that is not enabled by default. You must explicitly enable it in your Apigee hybrid configuration.

For more information, see Model Context Protocol (MCP) overview, Enable MCP for Apigee hybrid, and the MCP quickstart.

Feature

Root CA certificate rotation

Apigee hybrid v1.17.0 lets you rotate the root certificate authority (CA) certificate that anchors trust for TLS communication between your runtime components. You can now replace the root CA before it expires, without downtime.

For more information, see Rotate the root CA.

Feature

TLS 1.3 support

Apigee hybrid v1.17.0 adds support for TLS 1.3, a newer version of the Transport Layer Security (TLS) protocol that offers faster connection handshakes and stronger security than earlier TLS versions.

For information about configuring TLS on the ingress gateway, see Configuring TLS and mTLS on the Apigee ingress gateway.

Feature

Forward proxy support for AI policies

Apigee hybrid v1.17.0 adds forward proxy support for AI policies, such as the Model Armor and semantic caching policies. Outbound calls from these policies can now be routed through an HTTP forward proxy.

For more information, see Configure a forward proxy, Get started with the Model Armor policies, and Get started with semantic caching policies.

Feature

Semantic cache Private Service Connect (PSC) endpoint support

Apigee hybrid v1.17.0 adds Private Service Connect (PSC) endpoint support for semantic caching. The semantic caching policies can now reach their backing services over a Private Service Connect endpoint, which keeps that traffic on your private network.

For more information, see Configure semantic caching over Private Service Connect.

Feature

Semantic cache distance measure support

Apigee hybrid v1.17.0 adds support for non-default Vertex AI Vector Search distance measures in the SemanticCacheLookup policy. A new optional <DistanceMeasureType> element accepts DOT_PRODUCT_DISTANCE (the default, and the existing behavior), COSINE_DISTANCE, SQUARED_L2_DISTANCE, and L1_DISTANCE. The policy compares <Threshold> in the direction the declared measure implies, so declaring a non-default measure requires re-tuning the threshold in the same edit.

For more information, see SemanticCacheLookup policy.

Feature

Reduced service account permissions

Apigee hybrid v1.17.0 reduces the Google Cloud IAM permissions that Apigee service accounts require. Service accounts that use Cloud Storage now require only the storage.objects.get and storage.objects.create permissions rather than the broader Storage Admin (roles/storage.admin) role. The Cassandra components also no longer run with the privileged: true security context.

For more information about service accounts, see Create service accounts.

Security

Various security and CVE fixes are included in this release.

Backup and DR
Feature

You can now monitor restore jobs for Filestore instances directly from the Backup and DR Jobs page in the Google Cloud console. When you trigger a restore on a Filestore instance, Backup and DR automatically tracks the job progress and status.

For more information, see Restore a Filestore instance from a backup vault and Monitor backup and restore jobs in Google Cloud console.

BigQuery
Change

An updated version of the Simba ODBC driver for BigQuery is now available.

Feature

Metadata for BigQuery Graph is automatically ingested and searchable in Knowledge Catalog. This feature is available in preview.

Feature

You can now include a WHERE clause inside of an aggregate function call to filter your aggregate function input using a boolean expression. This feature is in Preview.

Bigtable
Feature

You can use the Google Cloud console to create, list, and query parameterized views for your Bigtable instances. You can also configure view parameters and run queries in Bigtable Studio. This feature is generally available (GA). For more information, see Create and manage parameterized views.

Cloud Logging
Feature

Starting with version 2.71.0, you can use an Ops Agent configuration option to export your metrics, logs, and traces by using the OpenTelemetry-based Telemetry API rather than by using the Cloud Monitoring API, Logging API, or Trace API For more information, see Use the Telemetry API.

Cloud Monitoring
Feature

Starting with version 2.71.0, you can use an Ops Agent configuration option to export your metrics, logs, and traces by using the OpenTelemetry-based Telemetry API rather than by using the Cloud Monitoring API, Logging API, or Trace API For more information, see Use the Telemetry API.

Cloud SQL for PostgreSQL
Feature

You can use the pg_textsearch extension in Cloud SQL for PostgreSQL to perform full-text search using the industry-standard BM25 (Best Matching 25) scoring algorithm for highly accurate relevance scoring.

This extension requires PostgreSQL 17 or later and is supported on PostgreSQL release R20260712.01_06 or later.

For more information, see Full-text search using pg_textsearch.

Cloud SQL for SQL Server
Deprecated

Beginning April 12, 2027, you won't be able to create new instances of Cloud SQL for SQL Server 2017. Starting on October 13, 2027, SQL Server 2017 will reach end of life (EOL) and Microsoft will stop releasing security updates. Cloud SQL for SQL Server will stop supporting SQL Server 2017 after this date.

For more information, see Database versions and version policies.

Cloud Workstations
Feature

Cloud Workstations supports customizing provisioned IOPS and throughput for Hyperdisk Balanced High Availability disks. This customization feature is in Preview.

Compute Engine
Feature

Preview: You can create regional disks, including Hyperdisk Balanced High Availability volumes, from custom and public OS images.

For more information, see Create and manage regional disks.

Gemini Enterprise Agent Platform
Deprecated

Gemini model deprecation and retirement date updates

The retirement and deprecation dates for the following Gemini models have been updated:

  • Gemini 2.5 Flash Image (gemini-2.5-flash-image): Deprecated and scheduled for retirement on March 15, 2027 (extended from October 2, 2026). Migrate to Gemini 3.1 Flash-Lite Image (gemini-3.1-flash-lite-image).
  • Gemini 3.1 Flash-Lite Image (gemini-3.1-flash-lite-image): Retirement date is scheduled for June 28, 2027 or later.

For more information, see Gemini model versions and lifecycle.

Fixed

CodeMender updates (v0.7.0)

This release introduces updates to CodeMender:

  • Network stream resilience: Improved CLI session stability with automatic reconnection and transient error recovery during long-running scans and remediation workflows.
  • Configuration uniformity: Standardized directory exclusion rules across configuration files and CLI scanning flags under scan_config.exclude_dirs.
  • Bug fixes:
    • Fixed an issue where cm report incorrectly categorized DISMISSED findings as OPEN in the summary table.
    • Resolved sandbox permission denial errors by preventing child worker processes from attempting to create internal session logs on disk.
    • Hardened sandbox command policy to prevent directory traversal and file inspection outside the designated repository root into adjacent directories.

For more information, see CodeMender documentation.

Feature

Cyber Verification Program for Claude is available in Preview

Anthropic's Cyber Verification Program (CVP) is available in Preview on Gemini Enterprise Agent Platform. CVP enables verified organizations to use supported Claude models (Claude Opus 4.7, Claude Opus 4.8, Claude Sonnet 5, and Claude Opus 5) for legitimate defensive cybersecurity tasks with default dual-use restrictions lifted.

For more information, see Cyber Verification Program for Claude.

Google SecOps
Feature

[Spotlight Feature] GoogleSQL query support in Search

This feature is in public preview. You can now use GoogleSQL in Search to query your security data in Google SecOps, offering a flexible and powerful industry-standard alternative to YARA-L 2.0. GoogleSQL is optimized for broad data exploration, statistical aggregation, and deep-dive ad hoc investigations. You can query telemetry tables including but not limited to UDM events, entity graphs, detection rules, and case management data—using either standard declarative SQL or the linear, sequential Piped SQL syntax.

For more information, see Get started with GoogleSQL.

Deprecated

MANDIANT_ACTIVE_BREACH_IOC,MANDIANT_FUSION_IOC, andOPEN_SOURCE_INTEL_IOC` feeds are being removed

The MANDIANT_ACTIVE_BREACH_IOC, MANDIANT_FUSION_IOC, and OPEN_SOURCE_INTEL_IOC feeds are deprecated in favor of the GTI_IOC feed. After March 18, 2027, we will be removing the MANDIANT_ACTIVE_BREACH_IOC, MANDIANT_FUSION_IOC, and OPEN_SOURCE_INTEL_IOC feeds. For more information on how to migrate, see Migrate Mandiant legacy feeds to GTI.

Google SecOps SIEM
Deprecated

MANDIANT_ACTIVE_BREACH_IOC,MANDIANT_FUSION_IOC, andOPEN_SOURCE_INTEL_IOC` feeds are being removed

The MANDIANT_ACTIVE_BREACH_IOC, MANDIANT_FUSION_IOC, and OPEN_SOURCE_INTEL_IOC feeds are deprecated in favor of the GTI_IOC feed. After March 18, 2027, we will be removing the MANDIANT_ACTIVE_BREACH_IOC, MANDIANT_FUSION_IOC, and OPEN_SOURCE_INTEL_IOC feeds. For more information on how to migrate, see Migrate Mandiant legacy feeds to GTI.

Knowledge Catalog
Feature

Metadata for BigQuery Graph is now automatically ingested and searchable in Knowledge Catalog. This feature is available in preview.

For more information, see Knowledge Catalog overview.

Network Intelligence Center
Feature

When adding a new Google Cloud Compute Engine, container, or VM Monitoring Point, Cloud Network Insights lets you generate Google Cloud CLI commands in the Google Cloud console to download Monitoring Point installation bundles.

Secret Manager
Feature

Parameter Manager supports CRC32C checksums to verify data integrity when you add or access parameter versions.

For more information, see Data integrity assurance.

Security Command Center
Deprecated

Data Security Posture Management is deprecated. It will be shut down on February 1, 2027. Learn more about the controls and alternative detection capabilities.

Vertex AI Search
Feature

Agent Search: Search query add-ons for configurable pricing (GA)

Search query add-on specifications (searchAddonSpec) for configurable pricing are generally available (GA) in the v1 API. You can use searchAddonSpec when you want to save money by turning off add-ons for individual search requests made programmatically.

For more information, see About controlling which add-ons apply to a search request and REST, per search request in Manage configurable pricing for search query add-ons.

September 13, 2026

Agent Platform Workbench
Change

20260911.00_p0 Release

Change

20260913.00_p0 Release

Change

Installed latest packages from upstream dependencies.

Change

Installed latest packages from upstream dependencies.

Fixed

Fixed the %%bigquery notebook cell magic, which returned an error instead of query results in JupyterLab 4.

Fixed

Fixed the %%bigquery notebook cell magic, which returned an error instead of query results in JupyterLab 4.

Change

20260913-2230-rc0 Release

Change

20260913-2230-rc0 Release

Change

Installed latest packages from upstream dependencies.

Change

Installed latest packages from upstream dependencies.

Fixed

Fixed an issue where the notebook-disable-nbconvert metadata flag was ignored in custom containers.

Change

The obsolete google-cloud-sdk transitional package is no longer installed. The Google Cloud CLI itself is unchanged; it was already provided by the google-cloud-cli package.

Fixed

Fixed the %%bigquery notebook cell magic, which returned an error instead of query results in JupyterLab 4.

Fixed

Fixed an issue where the notebook-disable-nbconvert metadata flag was ignored in custom containers.

Fixed

Fixed the %%bigquery notebook cell magic, which returned an error instead of query results in JupyterLab 4.

Change

20260913-2130-rc0 Release

Change

Installed latest packages from upstream dependencies.

Fixed

Fixed the %%bigquery notebook cell magic, which returned an error instead of query results in JupyterLab 4.

Change

M149 Release

Change

Installed latest packages from upstream dependencies.

Fixed

Fixed the %%bigquery notebook cell magic, which returned an error instead of query results in JupyterLab 4.

September 11, 2026

API Gateway
Feature

Enable Model Context Protocol (MCP)

You can now configure API Gateway to act as a remote Model Context Protocol (MCP) server. This Public Preview feature allows you to expose your existing REST APIs to AI agents as tools, without requiring changes to your backend services. You can enable MCP by annotating your OpenAPI 3.x specification using custom Google extensions.

For more information, see Model Context Protocol overview and Configure Model Context Protocol.

AlloyDB for PostgreSQL
Feature

You can now monitor the status, throughput, and backlog of the audit logging pipeline for your AlloyDB for PostgreSQL instances and nodes using Cloud Monitoring.

For more information, see Monitor audit log pipeline status.

Cluster Toolkit
Security

Google addressed multiple security vulnerabilities in Slurm that affect Cluster Toolkit. For more information, see the security bulletin.

Compute Engine
Feature

Preview: You can view Workload Manager rule findings directly on the Compute Engine Overview page in the Google Cloud console. The Workload Manager findings tile lets you identify configuration risks for your compute instances and resources against best practices for reliability and security.

For more information, see View Workload Manager rule findings in Compute Engine.

Google Cloud Contact Center as a Service
Announcement

Google Cloud CCaaS 6.12

We've released version 6.12 of Google Cloud CCaaS.

The timing of the update to your instance depends on the deployment schedule that you have chosen. For more information, see Deployment schedules.

Feature

Cold transfers auto-resume

When an agent performs a cold transfer, the call now resumes at the moment the receiving agent answers the call. The receiving agent no longer needs to manually take the caller off hold. This eliminates the silence that previously occurred between an agent answering a call and taking the caller off hold.

For more information, see Cold transfers.

Feature

Hubspot: Configure Do Not Call by phone number

In HubSpot integrations, you can now configure Do Not Call for specific phone numbers instead of for an entire contact or company record. Opt-out matching is no longer case-sensitive.

Administrators: There's a new Do Not Call Configuration section in the CRM pane, located at Settings > Developer Settings (with HubSpot selected).

For more information, see Configure Do Not Call for HubSpot.

Feature

Agent desktop: New network diagnostics tool

The agent desktop has a new network diagnostics tool in the navigation menu that displays network strength and diagnostics information. This tool can help you quickly assess your network's health and troubleshoot connection issues.

For more information, see Get network diagnostic information.

Feature

Agent desktop: Open from the CCaaS portal

You can now access the Agent Desktop using the new Apps menu. In the CCaaS portal, click Apps > Agent Desktop to open the Agent Desktop in a new browser tab. This lets you move between the portal and the Agent Desktop without ending your portal session.

For more information, see Open the agent desktop.

Fixed

This release addresses the following issues:

  • Fixed an issue where SmartAction statuses were incorrectly marked as "failed" when a call ended before a photo or video upload completed.

  • Fixed an issue where loading the outbound numbers list timed out or caused significant delays for organizations with large teams and custom roles.

  • Fixed an issue where estimated wait times of less than one minute were incorrectly rounded down to zero, preventing the system from accurately triggering over-capacity actions.

  • Fixed an issue where sudden spikes in call volume bypassed a team's capacity protections and reduced the team's agent availability to below configured minimums.

  • Fixed an issue where nested object values in custom data were incorrectly displayed as [object Object] in the agent desktop session data feed.

  • Fixed an agent desktop issue where the navigation bar in the Previous Interactions page of the call adapter was overlapped by summary text and didn't stay fixed while scrolling.

  • Fixed an issue where answered voice calls triggered a second, unrequested callback after the end-user hung up.

  • Fixed an issue where intermittent IMAP connection rejections caused email fetch workers to enter an extended backoff loop, resulting in several hours of mailbox downtime.

  • Fixed an issue where inbound voice call recordings weren't exported to external storage when a virtual agent escalation was deflected to voicemail due to over-capacity.

  • Fixed an issue where manual wrap-up sessions were incorrectly attributed to the most recent call in the Agent Activity Timeline and in raw data exports, even when the wrap-up was unrelated to that call.

  • Fixed an issue where the "agent leg" of a call connection stalled in a connecting state for the full timeout duration before failing silently and moving the agent to an available status.

  • Fixed an issue where custom form responses weren't exported to external storage for instances without an external CRM integration.

  • Fixed an issue where a queue name saved in the SLA thresholds for queues dialog didn't persist after saving.

  • Fixed an issue where virtual agent voice calls triggered a session error during wrap-up.

  • Fixed an issue during high-capacity redirections where voicemails weren't saved.

  • Fixed an issue where completed call transfers generated duplicate queue duration records, leading to inflated reporting for queue volume and SLA metrics.

  • Fixed an agent desktop issue where the sentiment banner in the call adapter didn't immediately appear at the start of a call.

  • Fixed an issue where saving the Upload audio recording for Language Selection option of the Languages dialog didn't persist and switched to Text-to-speech.

  • Fixed an issue where inefficient database queries caused high CPU utilization and performance degradation across all communication channels.

  • Fixed an issue where transient connection errors during Twilio ICE token fetching caused agent call setup to fail or take longer to connect.

  • Fixed an issue where temporary connection drops during chat webhook delivery caused unnecessary delays.

  • Fixed an issue where work time and wait time durations overlapped in reporting metrics.

  • Fixed an issue where the agent adapter call history incorrectly displayed English queue names for French-Canadian calls.

  • Fixed an issue where agents were assigned calls from secondary queues even when their primary queue fell below the minimum availability threshold.

  • Fixed an issue where canceled virtual-agent-to-human escalations incorrectly reported negative queue durations and inaccurate SLA metrics in chat session data and reports.

  • Fixed an issue where creating or updating queues failed and returned a timeout error.

  • Fixed an agent desktop issue where an outbound call canceled by an agent while connecting was recorded as an unknown failure instead of an agent cancellation.

  • Fixed an issue where clicking the rewind and forward buttons on the voicemail page of the call adapter restarted the voicemail from the beginning.

  • Fixed an agent desktop issue where the chat adapter displayed a loading progress indicator instead of the chat transcript when a chat session was assigned.

  • Fixed an issue where a disposition prompt didn't appear in the call adapter after a disconnected call, even when mandatory disposition was configured.

  • Fixed an issue where Agent Assist real-time transcription didn't start on Vonage BYOC calls.

  • Fixed an issue where changes made outside of browser-originated HTTP requests (such as from API clients or background jobs) failed to generate audit log records.

  • Fixed an issue where over-capacity phone deflection didn't activate for direct agent calls, resulting in an error message or callers waiting indefinitely.

  • Fixed an issue where transient network connection failures during call and chat DAP lookups caused inbound calls to route to default queues or prevented chat sessions from starting.

  • Fixed a web SDK issue where static, non-interactive text within the chat widget incorrectly received keyboard focus, disrupting the navigation flow for keyboard and screen reader users.

  • Fixed an issue where temporary asset errors during deployments were cached by the CDN, leading to web SDK initialization failures.

  • Fixed an agent desktop issue where incomplete configuration settings prevented call control buttons from updating or rendering properly.

  • Fixed an issue where the audio for an over-capacity deflection played in the source queue's language instead of the destination queue's language following a cross-language transfer.

  • Fixed an issue where waiting chats weren't immediately offered to available agents who became eligible for a queue through a team membership update or direct queue assignment.

Google Kubernetes Engine
Feature

Agent Substrate on GKE is now available for evaluation and non-production use. Production support is offered on an allowlist basis under a limited GA program.

Agent Substrate runs agentic workloads at scale on GKE clusters. To reduce resource usage, Agent Substrate suspends idle agents and takes a snapshot of the agent's active memory (RAM) and local files. When a suspended agent is triggered, the system restores the agent's state onto an available sandbox with sub-second latency.

Agent Substrate improves on the capabilities of Agent Sandbox by bypassing the bottlenecks of the standard Kubernetes control plane to run significantly more concurrent agents per machine.

For more information, see About GKE Substrate.

Google SecOps
Deprecated

Deprecation of write permissions from the chronicle.readonly OAuth scope

Effective January 25, 2027, write permissions will be removed from the chronicle.readonly OAuth scope, restricting it strictly to read operations. You can continue using chronicle.readonly for read operations. Make sure you update any workflows performing write operations to use the chronicle OAuth scope.

Google SecOps SIEM
Deprecated

Deprecation of write permissions from the chronicle.readonly OAuth scope

Effective January 25, 2027, write permissions will be removed from the chronicle.readonly OAuth scope, restricting it strictly to read operations. You can continue using chronicle.readonly for read operations. Make sure you update any workflows performing write operations to use the chronicle OAuth scope.

Spanner
Feature

Spanner Graph supports the following enhancements for CREATE PROPERTY GRAPH:

  • Semantic options for labels and properties: You can configure OPTIONS (description and synonyms) on labels and properties to provide context and improve discoverability for natural language querying interfaces.
  • Element key uniqueness validation option: You can configure the validate_element_key_uniqueness option in the property graph OPTIONS clause to control whether Spanner Graph validates element key uniqueness at schema creation time.

For more information, see CREATE PROPERTY GRAPH statement and Disabled key validation.

September 10, 2026

Apigee X
Fixed

Addendum to Apigee release notes dated August 27, 2026 (1-18-0-apigee-4).

Bug ID Description
502540992 Fixed an issue where the SemanticCacheLookup policy was incompatible with Vertex AI Vector Search Private Service Connect (PSC) endpoints.
BigQuery
Feature

Conversational analytics in BigQuery now supports the ML.CORRELATION function to calculate statistical correlations between a target column and one or more metric columns in a table. This feature is in Preview.

Feature

You can now use the ML.METRICS function to compute evaluation metrics for machine learning classification or regression tasks on any table or query that contains actual and predicted values. This function lets you evaluate predictions without needing to create or reference a stored model. This feature is in Preview.

Feature

You can use the AI.CAUSAL_EFFECT function to quantify the impact of specific interventions on time series data. This feature is in Preview.

Feature

The Data Engineering Agent now integrates with BigQuery Graph to provide additional context between your data source and destination schema, and improves schema mapping accuracy for your data engineering pipelines.

This feature is generally available (GA).

Cloud SQL for MySQL
Breaking

Appending sqlcommenter tags using the sql_commenter_enabled parameter when executing SQL queries on a Cloud SQL remote MCP server is temporarily disabled.

For more information, see sqlcommenter tags.

Cloud SQL for PostgreSQL
Breaking

Appending sqlcommenter tags using the sql_commenter_enabled parameter when executing SQL queries on a Cloud SQL remote MCP server is temporarily disabled.

For more information, see sqlcommenter tags.

Cloud Storage
Feature

Storage Intelligence advisor is now generally available. Storage Intelligence advisor lets you monitor and manage your Cloud Storage environment at scale across organizations, folders, and projects. For more information, see About Storage Intelligence advisor.

Gemini Enterprise
Feature

Gemini Enterprise: Pay-as-you-go edition and AI developer tools available for all invoiced Cloud Billing accounts

Subscribing to the Gemini Enterprise Pay-as-you-go edition and accessing AI developer tools is available to all projects linked to an invoiced Cloud Billing account. Previously, only customers who received an email with the subject line [Billing Update] New Gemini Enterprise overage billing controls launching Aug 17, 2026 could access AI developer tools. This restriction no longer applies.

For more information, see:

Feature

Gemini Enterprise: Support for channel mentions and multi-turn conversations in the Gemini Enterprise app for Slack

The Gemini Enterprise app for Slack has the following new capabilities:

  • Channel mentions: You can @mention the Gemini Enterprise app directly in Slack channels and conversational threads. The app returns responses privately so you can review them before choosing to share.
  • Multi-turn conversations: The Gemini Enterprise app remembers the context of your current session in direct messages. You can ask follow-up questions and refine previous responses. You can clear the context and start over by clicking New chat.

To enable these features, your Slack administrator must reinstall the Gemini Enterprise app. For more information, see Install the Gemini Enterprise app for Slack in your Slack workspace. After the administrator reinstalls the app, end users must authorize the Slack connector. For more information, see User authorization. If you don't reinstall and re-authorize the Gemini Enterprise app, your Slack workspace retains the legacy experience.

These features are generally available (GA). For more information, see Configure the Gemini Enterprise app for Slack.

Gemini Enterprise Agent Platform
Feature

Provisioned Throughput: Support for multiple pending orders and change requests

Provisioned Throughput now directly supports from the self service console the ability to schedule multiple new orders at the same time and change requests across multiple orders within the same project.

For more information, see Purchase Provisioned Throughput.

Google Cloud Managed Service for Apache Kafka
Feature

You can configure a Managed Service for Apache Kafka cluster as a public cluster to let client applications connect over the public internet. For more information, see Connect clients to a public cluster.

Identity and Access Management
Feature

The Identity and Access Management (IAM) Model Context Protocol (MCP) server is generally available. You can connect to the IAM remote MCP server from AI applications to inspect and manage custom roles and deny policies across your resources.

For more information, see the following documentation:

Looker
Feature

The Looker extension for VS Code is now generally available, enabling local LookML development and AI-assisted "vibe coding" using the Model Context Protocol (MCP). This update introduces an interactive onboarding walkthrough, support for populating workspaces from bare repositories, and enhanced synchronization between local Git branches and Looker Development Mode. Additional improvements include support for OAuth with the Kiro IDE and more secure storage of API client secrets.

Network Connectivity Center
Feature

Support for global Google APIs for endpoint propagation through Network Connectivity Center is available in Preview.

For information about the new quota for propagated global Google APIs, see NCC quotas.

Virtual Private Cloud
Feature

Preview: Propagated connections support Private Service Connect endpoints that access global Google APIs. With propagated connections, endpoints that access global Google APIs in one consumer VPC spoke can be privately accessed by other consumer VPC spokes that are connected to the same Network Connectivity Center hub.

September 09, 2026

Apigee X
Feature

SemanticCacheLookup policy supports non-default Vector Search distance measures

Available in Apigee 1-18-0-apigee-4 and later. A new optional <DistanceMeasureType> element accepts DOT_PRODUCT_DISTANCE (the default, and the existing behavior), COSINE_DISTANCE, SQUARED_L2_DISTANCE and L1_DISTANCE. The policy now compares <Threshold> in the direction the declared measure implies, so declaring a non-default measure requires re-tuning the threshold in the same edit. The 0-to-1 restriction on <Threshold> is also removed.

BigQuery
Feature

BigQuery generative AI functions now support the following Gemini models:

  • gemini-3.5-flash-lite
  • gemini-3.6-flash
  • gemini-3.7-flash
Cloud Monitoring
Feature

A chart on a dashboard can override the dashboard's time-range setting. This feature lets you view trends over a long period or metric data with low sampling rates alongside charts that show only recent data, and is Generally Available (GA).

For more information, see the following documents:

Gemini Enterprise
Breaking

Gemini Notebook Enterprise: Website URL ingestion blocked by VPC Service Controls

Projects with VPC Service Controls enabled can't add website URLs as notebook sources in Gemini Notebook Enterprise.

This is because direct website ingestion performs a live web crawl, generating outbound traffic beyond Google networks, which would violate VPC Service Controls perimeter policies.

Other source types, such as Google Docs and YouTube URLs, remain supported in projects with VPC Service Controls enabled.

Gemini Enterprise Agent Platform
Feature

Computer Use and Shell sandboxes are generally available

Computer Use and Shell sandboxes in Gemini Enterprise Agent Platform are now generally available (GA). This release also includes the following new features for Agent Platform sandboxes:

  • Shell sandboxes: Run untrusted shell commands, install packages, and manipulate files in an isolated Linux container using direct API /exec calls. For more information, see the Shell sandbox quickstart.

  • VPC Service Controls & Private Service Connect: Protect sandbox data and isolate network boundaries with VPC Service Controls, private ingress endpoints (PSC-E), and private egress routing (PSC-I). For more information, see Configure VPC Service Controls and Private Service Connect with sandboxes.

  • Customer-Managed Encryption Keys (CMEK): Protect sandbox data at rest, including disk storage and snapshot checkpoints, using Cloud KMS keys. For more information, see Configure customer-managed encryption keys (CMEK) for sandboxes.

  • Pausing and resuming sandboxes: Deschedule compute resources for idle sandboxes while preserving file system state and connection identity, and resume them in seconds. For more information, see Manage sandboxes.

Feature

Priority PayGo now supports the US and EU multi-region endpoints

You can send Priority PayGo requests to the us and eu multi-region endpoints, in addition to the global endpoint.

For more information, see Priority PayGo.

Feature

Agent Gateway supports multiple Agent Registry instances

Agent Gateway now lets you associate up to two Agent Registry instances (one global registry and one regional or multi-region registry) with a single Agent Gateway instance. For more information, see Register your agents and destination resources.

Feature

Agent Gateway supports VPC Service Controls

Agent Gateway now enforces VPC Service Controls perimeter rules for agent communications. When you configure Agent Gateway with VPC connectivity, agent traffic is routed through your private VPC network, ensuring that your organization's VPC-SC perimeter rules are applied to all agent traffic as well.

Note that setting up VPC connectivity is required to enable VPC Service Controls perimeter enforcement for Agent Gateway deployments. The connectivity template must be configured in ALL_TRAFFIC egress mode.

Google SecOps Marketplace
Feature

Google Chronicle: Version 95.0

  • The following new action has been added:

    • Is Value In Data Table Async
Change

Microsoft 365 Defender: Version 31.0

  • Updated alert tracking logic, extracted alert object metadata, and improved the pagination and timeout handling mechanism in the following connector:

    • Microsoft 365 Defender - Incidents Connector
Change

Google Chronicle: Version 95.0

  • Integration: Improved OAuth 2.0/JWT authentication logging, validation diagnostics, and error messaging.
Change

Trend Vision One: Version 12.0

  • Made the Description parameter mandatory in the following actions:

    • Isolate Endpoint

    • Unisolate Endpoint

Identity and Access Management
Feature

You can get IAM role suggestions from Gemini programmatically by using the Policy Assist API (Preview).

For more information, see the following documentation:

Looker
Deprecated

The deprecation of the Looker Mobile (Legacy) application has been postponed to January 31, 2027. Starting on January 31, 2027, support for the Looker Mobile (Legacy) app will be discontinued and the app will be unavailable for download from the App Store or Play Store. Although users will still be able to use the Looker Mobile (Legacy) app if they already have it installed, we recommend that you install the non-legacy Looker mobile app.

NetApp Volumes
Announcement

Google Cloud NetApp Volumes now supports the Flex Unified service level in the following regions:

  • asia-east1 (Taiwan)

  • australia-southeast2 (Melbourne)

  • europe-southwest1 (Madrid)

For more information about available regions, see Supported regions.

Network Intelligence Center
Feature

You can deploy Monitoring Points optimized for Amazon Web Services (AWS) or Microsoft Azure cloud infrastructure from Cloud Network Insights.

Policy Intelligence
Feature

The Policy Assist remote MCP server is available in Preview. To learn about using the Policy Assist remote MCP server to let external AI agents and applications suggest IAM roles, see Use the Policy Assist remote MCP server and the Policy Assist MCP reference.

Feature

The Policy Assist REST API is available in Preview. Policy Assist lets you get IAM role suggestions for individual principals with AI assistance.

To learn about using the Policy Assist API to get role suggestions programmatically, see the Policy Assist REST reference.

September 08, 2026

Agent Platform Workbench
Fixed

Scheduled upgrade metadata is validated

The value of the notebook-upgrade-schedule metadata key is now validated when you create or update an Agent Platform Workbench instance. The value must be a single-line unix-cron format schedule. For more information, see Manage features through metadata.

Assured Workloads
Feature

The EU Data Boundary with Access Justifications supports the following products:

  • AlloyDB for PostgreSQL
  • Apigee
  • Eventarc
BigQuery
Feature

Conversational analytics now supports predictive modeling questions using the AI.PREDICT function. This feature is in Preview.

Cloud Run
Feature

To take advantage of reduced pricing for Cloud Run jobs, you can delay job execution to defer non-urgent tasks for up to 12 hours (Preview).

Cloud SQL for MySQL
Feature

Regional endpoints (REP) are now generally available (GA) for the Cloud SQL for MySQL Admin API.

Regional endpoints let you interact with Cloud SQL for MySQL instances using regionalized URLs (such as sqladmin.{region}.rep.googleapis.com) rather than through a single global endpoint.

Regional endpoints provide regional frontend and load balancing infrastructure that improves data residency by keeping network traffic within the same region as the instance. This reduces the instance's dependency on global frontend infrastructure.

Regional endpoints have strong regional isolation, so the failure of a load balancer or frontend in one region doesn't affect any other region. Regional service load balancers have a separate, regionally isolated control plane.

Regional endpoints are designed to meet stringent data residency and sovereignty standards, such as ITAR and Assured Workloads Regions, ensuring data in transit remains within the committed region.

Certificate management and TLS termination occurs within each region, on the regional load balancer, so data remains encrypted until it reaches its destination region and stays within that region while being processed there.

Cloud SQL for PostgreSQL
Feature

Regional endpoints (REP) are now generally available (GA) for the Cloud SQL for PostgreSQL Admin API.

Regional endpoints let you interact with Cloud SQL for PostgreSQL instances using regionalized URLs (such as sqladmin.{region}.rep.googleapis.com) rather than through a single global endpoint.

Regional endpoints provide regional frontend and load balancing infrastructure that improves data residency by keeping network traffic within the same region as the instance. This reduces the instance's dependency on global frontend infrastructure.

Regional endpoints have strong regional isolation, so the failure of a load balancer or frontend in one region doesn't affect any other region. Regional service load balancers have a separate, regionally isolated control plane.

Regional endpoints are designed to meet stringent data residency and sovereignty standards, such as ITAR and Assured Workloads Regions, ensuring data in transit remains within the committed region.

Certificate management and TLS termination occurs within each region, on the regional load balancer, so data remains encrypted until it reaches its destination region and stays within that region while being processed there.

Cloud SQL for SQL Server
Feature

Regional endpoints (REP) are now generally available (GA) for the Cloud SQL for SQL Server Admin API.

Regional endpoints let you interact with Cloud SQL for SQL Server instances using regionalized URLs (such as sqladmin.{region}.rep.googleapis.com) rather than through a single global endpoint.

Regional endpoints provide regional frontend and load balancing infrastructure that improves data residency by keeping network traffic within the same region as the instance. This reduces the instance's dependency on global frontend infrastructure.

Regional endpoints have strong regional isolation, so the failure of a load balancer or frontend in one region doesn't affect any other region. Regional service load balancers have a separate, regionally isolated control plane.

Regional endpoints are designed to meet stringent data residency and sovereignty standards, such as ITAR and Assured Workloads Regions, ensuring data in transit remains within the committed region.

Certificate management and TLS termination occurs within each region, on the regional load balancer, so data remains encrypted until it reaches its destination region and stays within that region while being processed there.

Cloud Trace
Feature

The Observability API supports VPC Service Controls. This integration is generally available.

For more information, see the following:

Compute Engine
Feature

Generally available: You can convert a single-project reservation into a shared reservation, or a shared reservation into a single-project reservation. Modify the share type for a reservation to share your reserved resources with other projects in your Google Cloud organization, or to restrict access to only the reservation's owner project. For more information, see Modify the share type for a reservation.

Config Connector
Announcement

Config Connector version 1.156.0 is now available.

Feature

New Alpha Resources (Direct Reconciler):

Feature

New Fields: